Skip to content
TECH CEO Daily

Cloudflare plans a public certificate authority with post-quantum certs in early 2027

Cloudflare has agreed to buy a GlobalSign root and applied to browser root programs. It plans free, automated certificates and post-quantum ones from early 2027.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Cloudflare announced on September 29 that it intends to become a public certificate authority but is not issuing certificates yet.
  • 2It has agreed to acquire a GlobalSign root and plans its first Merkle Tree Certificates in the first quarter of 2027.
  • 3Security teams should inventory certificates, confirm ACME automation and ask current issuers about post-quantum roadmaps.

The news

Cloudflare (NET) said on September 29 that it intends to become a public certificate authority, a trusted issuer of the digital certificates browsers use to confirm a website is genuine, and plans to issue post-quantum certificates starting in the first quarter of 2027.

In a blog post, Cloudflare said it has signed a definitive agreement to acquire an established root from GlobalSign. A root is the top-level certificate that browsers and devices already trust, and Cloudflare said this one has been trusted across browsers, operating systems and devices since 2012. The company has also applied to the root programs run by Chrome, Apple, Microsoft and Mozilla, which decide which issuers their software trusts. Deal terms were not disclosed.

Cloudflare is not issuing certificates yet and said it will be a while before it does. SiliconANGLE reported that conventional issuance will start once the browser root programs accept the applications, and that the company gave no date. Cloudflare said certificates will be free and issued only through ACME, an open standard for automated issuance and renewal, to clients that support ACME Renewal Information, a newer extension standardized as RFC 9773.

The post-quantum piece centers on Merkle Tree Certificates, a compact format meant to keep connections fast once certificates switch to signatures that quantum computers cannot break. Those signatures are much larger: SiliconANGLE reported that output from one newly standardized post-quantum algorithm runs to 2,420 bytes, against 64 bytes for the elliptic curve schemes in wide use. Cloudflare said it plans to be one of the first issuers of production Merkle Tree Certificates and that Chrome has named the format its preferred path for post-quantum authentication.

Cloudflare framed the move as a resilience play. It said that if the dominant free issuer had a bad week, much of the web would have no comparable free, automated alternative. Cloudflare said Let's Encrypt issues on the order of ten million certificates a day and serves more than 500 million sites. Chief Executive Matthew Prince called upgrading the web's security before quantum computers can break it "one of the biggest coordination challenges in the history of the internet," according to SiliconANGLE.

Cloudflare, which says it handles more than 20 percent of global internet request traffic, said it will keep working with the 16 partner public issuers it has relied on for years.

The numbers

First Merkle Tree Certificates planned
Q1 2027
GlobalSign root trusted since
2012
Partner public CAs Cloudflare relies on
16
Post-quantum vs elliptic curve signature size
2,420 bytes vs 64 bytes (SiliconANGLE)
Let's Encrypt issuance, per Cloudflare
About 10 million certificates a day
Cloudflare share of global internet request traffic
More than 20%, per Cloudflare

Why CEOs should care

For CISOs and IT leaders, the useful step is an inventory. List every system that holds a public certificate, including websites, APIs, load balancers and customer-facing devices, and note which ones renew automatically through ACME. Certificate lifetimes are already shrinking: under an industry ballot approved in April 2025, the maximum dropped to 200 days on March 15, 2026, falls to 100 days on March 15, 2027 and reaches 47 days on March 15, 2029. Any certificate still renewed by hand is a future outage.

For technology buyers and CFOs, a second large free issuer changes the negotiating picture. Ask current certificate vendors three questions: when will you support Merkle Tree Certificates or other post-quantum formats, do you support ACME Renewal Information, and what does our contract cover that a free issuer does not? Cloudflare customers should also ask whether the free Universal SSL certificates Cloudflare provides them will move to the new issuer, and when.

For boards, the point is timing, not panic. Cloudflare has not issued a single certificate yet, and its root applications still need approval. But Prince's framing of post-quantum migration as a massive coordination job matches how long these changes take. Boards should ask who owns the post-quantum plan and whether older systems that cannot handle new certificate formats have been identified.

The bigger picture

Cloudflare's argument is about concentration. By its own description, the dominant free issuer, the nonprofit Let's Encrypt, serves more than 500 million sites, and a second free provider at scale would give the web a fallback. It also moves more of the internet's trust plumbing into a company that already sits in front of a large share of web traffic, a trade-off root programs and customers will weigh. Let's Encrypt said in June that it expects to issue Merkle Tree Certificates in production in 2027, SiliconANGLE reported, so both large free issuers are converging on the same format.

What’s next

Watch for decisions from the Chrome, Apple, Microsoft and Mozilla root programs, the closing of the GlobalSign deal, and whether Cloudflare meets its first-quarter 2027 target for Merkle Tree Certificates. Until then, the practical work is automating renewals and building an inventory that will show which systems need new certificates.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

CloudflareGlobalSignLet's EncryptPost-quantum cryptography

Earlier coverage of Cloudflare

All Cloudflare coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.